LWN.net Logo

A privilege escalation flaw in udev

A privilege escalation flaw in udev

Posted Apr 22, 2009 18:05 UTC (Wed) by pheldens (guest, #19366)
Parent article: A privilege escalation flaw in udev

Is there a quick fix to fix a running system without downtime?


(Log in to post comments)

A privilege escalation flaw in udev

Posted Apr 22, 2009 18:25 UTC (Wed) by tzafrir (subscriber, #11501) [Link]

Kill udevd :-(

On a server system it should work.

A privilege escalation flaw in udev

Posted Apr 23, 2009 0:42 UTC (Thu) by smithj (subscriber, #38034) [Link]

The RHEL update for this issue automatically restarts udev. I would imagine other vendors either do the same or that /etc/init.d/udev restart (or similar) would be safe to execute on an in-production system.

A privilege escalation flaw in udev

Posted Apr 23, 2009 8:45 UTC (Thu) by janfrode (subscriber, #244) [Link]

The Red Hat errata for this fix says:
Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.
Is that just the normal cop out, or are there any reasons to worry upgrading udev on a RHEL5u0 will break something.. ?

A privilege escalation flaw in udev

Posted Apr 23, 2009 13:25 UTC (Thu) by cesarb (subscriber, #6266) [Link]

I have seen that sentence in every single security advisory they issue, so it is probably just a boilerplate sentence (of course, one can expect there are reasons for them adding that boilerplate).

A privilege escalation flaw in udev

Posted Apr 23, 2009 16:07 UTC (Thu) by janfrode (subscriber, #244) [Link]

And just to be on the paranoid safe side I asked Red Hat support, and they confirmed it should be safe to upgrade on any RHEL5 update levels.

A privilege escalation flaw in udev

Posted Apr 24, 2009 18:43 UTC (Fri) by smithj (subscriber, #38034) [Link]

FYI, I updated udev only on various RHEL5 boxen from 5.1 to 5.3, with weird patch levels in-between. I've yet to see any problems.

Your milage may vary.

A privilege escalation flaw in udev

Posted Apr 22, 2009 18:28 UTC (Wed) by proski (subscriber, #104) [Link]

Upgrading udev should not cause any downtime.

A privilege escalation flaw in udev

Posted Apr 22, 2009 19:16 UTC (Wed) by pranith (subscriber, #53092) [Link]

doesnt udevd keep track of all the devices it created??

A privilege escalation flaw in udev

Posted Apr 22, 2009 21:12 UTC (Wed) by jengelh (subscriber, #33263) [Link]

Maybe, but none that I know would be relevant to interruption like upgrade.

A privilege escalation flaw in udev

Posted Apr 22, 2009 21:46 UTC (Wed) by arjan (subscriber, #36785) [Link]

yes but it does that in a tiny database in /dev ... so persistent between udev restarts...

reboot?

Posted Apr 23, 2009 7:03 UTC (Thu) by jabby (guest, #2648) [Link]

so, no reboot is necessary for the kernel to use the new udev?

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds